<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MailChannels Blog</title>
	<atom:link href="http://www.mailchannels.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mailchannels.com/blog</link>
	<description>Covering spam protection and email technology</description>
	<lastBuildDate>Fri, 15 Mar 2013 18:19:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Fifty questions for Spamhaus, with our answers</title>
		<link>http://www.mailchannels.com/blog/2013/03/fifty-questions-for-spamhaus-with-our-answers/</link>
		<comments>http://www.mailchannels.com/blog/2013/03/fifty-questions-for-spamhaus-with-our-answers/#comments</comments>
		<pubDate>Fri, 15 Mar 2013 18:19:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trend Analysis]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=622</guid>
		<description><![CDATA[Ken Magill, who writes a weekly marketing blog called &#8220;The Magill Report&#8221;, recently solicited his readers to submit questions for Steve Linford, principle at Spamhaus. Ken&#8217;s readers sent in 51 questions, and I thought it would be fun to take a crack at answering them. Here goes: 1. How can Spamhaus work directly with legitimate [...]]]></description>
			<content:encoded><![CDATA[<p>Ken Magill, who writes a weekly marketing blog called &#8220;The Magill Report&#8221;, recently solicited his readers to <a href="http://www.magillreport.com/Questions-for-Spamhaus-Update/">submit questions for Steve Linford</a>, principle at Spamhaus. Ken&#8217;s readers sent in 51 questions, and I thought it would be fun to take a crack at answering them. Here goes:</p>
<p><b>1. How can Spamhaus work directly with legitimate marketers when issues arise? Wouldn’t it best serve customers and the overall email industry to resolve issues in good faith (as opposed to staying at arms’ length)?</b></p>
<p>Spamhaus already works directly with marketers &#8211; at least, those marketers who are reputable enough to attend conferences like <a href="http://www.m3aawg.org">M3AAWG</a>. Spamhaus contributes very actively in such forums, and in a constructive way to help marketers understand how to behave in such a way that they won&#8217;t qualify for a listing.</p>
<p><b>2. As more retailers offer to “email your receipt” in stores, the problem of miss-typed email addresses is likely to increase, and hitting Spamhaus traps will be more prevalent. Is there some way for Spamhaus to “ignore” emails that it gets from retailers when they see a capture event type (like a receipt)? Could they eventually focus instead on ensuring that marketers have good list hygiene by ensuring that the email is no longer mailed 12 months after not activating? Or what would they recommend?</b></p>
<p>I don&#8217;t think Spamhaus has a problem with stores sending out the odd receipt to an incorrect address. The problem was stores that then went on to send that email address marketing messages. If a customer provides their address to receive a receipt, then a receipt is really all they should get. It seems rather disingenuous for the store to assume that a bit of marketing would be acceptable.</p>
<p><b>3. How is Spamhaus working with legitimate marketers to improve list hygiene? Do they have a list of ‘best practices’ that they’d ideally like brands to follow that are business friendly (getting that customer email address) as well as good for business (legitimate email address)?</b></p>
<p>We would recommend applying to join <a href="http://www.m3aawg.org">M3AAWG</a>. Short of that, read the many published documents provided by M3AAWG, which anyone can use to greatly improve their overall mailing practices.</p>
<p><b>4. Does Spamhaus use email addresses that were used to subscribe to mailing lists and then discarded? Do old Yahoo, Gmail addresses become spam traps? How old? Also are they being tracked by Spamhaus?</b></p>
<p>I don&#8217;t think any anti-spam operation worth their salt would ever disclose what types of email addresses are used as spam traps. Generally speaking, however, a good spam trap is an address that was never used for legitimate emailing &#8211; including belonging to a mailing list. It would be very poor practice to scrape addresses from old mailing lists and turn them in to traps (say, by purchasing those expired domains). The people I talk to in the industry &#8211; who run good traps &#8211; take extensive precautions to avoid using addresses that may still receive legitimate email.</p>
<p><b>5. Are Spamhaus listings [ever] based on complaints sent to them?</b></p>
<p>I would speculate that some listings are based on complaints, but that most are based on Spamhaus&#8217; original research.</p>
<p><b>6. If hitting spamtraps is the only criterion what is the threshold?</b></p>
<p>If Spamhaus were to reveal their thresholds, then this would permit spammers to game the system by simply limiting the number of times they hit each email address in their lists. So, count on Spamhaus never revealing anything about the algorithms they use to select an IP for listing based on trap hits.</p>
<p><b>7. How is Spamhaus certifying an ESP? What is the criteria? [Steve, I have no idea what this refers to. I considered deleting it, but included it thinking you might know what he’s asking.]</b></p>
<p>To my knowledge, Spamhaus is not in the business of certifying ESPs. If you want to be certified, contact Return Path.</p>
<p><b>8. When Spamhaus created their whitelist they chose not to permit “marketing of any sort” or permit any company applying who used an ESP. Because Spamhaus is in a uniquely privileged position with their whitelist, they could have helped the email industry with a new standard of trust. Why did they choose not to do this?</b></p>
<p>If this is true, my guess is that ESPs generally have such a poor track record that it would be difficult for Spamhaus to pick and choose the very few ESPs who behave well enough to warrant being on the SWL.</p>
<p><b>9. Does Spamhaus believe that email should be delivered to consumers who have opted-in to email marketing from brands? [I know the short answer is yes, but left this one in in case you want to elaborate.]</b></p>
<p>I would say yes, with the following caveats: a) the consumer needs to know he or she is opting in to receive marketing messages, and b) the messages subsequently need to be highly correlated with what the consumer thought he or she would be receiving.</p>
<p><b>10. How can professional email marketers who wish to get opt-in emails delivered work with Spamhaus and other important providers of spam detection to help ensure spam is not delivered and other communications are? [Here again, I know the short answer is stop spamming, but I left it in anyway.]</b></p>
<p>Isn&#8217;t &#8220;professional email marketing&#8221; the art of getting stuff delivered that maybe shouldn&#8217;t get delivered?</p>
<p><b>11. What is their goal with CSS and do they feel their achieving it? Are they catching the “bad guys” so to speak or could it be acknowledged that ‘babies are being thrown out with the bathwater’? [This one’s from a reader who says they’re doing everything right and yet got caught in you anti-show-shoe spamming efforts somehow.]</b></p>
<p>The goal is clearly laid out on the Spamhaus CSS page:</p>
<blockquote><p>
As a snowshoe spreads the weight of a traveler across a wide area of snow, snowshoe spammers spread their spam output across many IPs and domains, diluting reputation metrics and evading filters. Snowshoe spammers frequently use many fictitious business names (DBAs), false names and identities, concealed anonymous domains and frequently changing postal dropboxes and voicemail drops to prevent others from connecting snowshoe spam operations to one another and recognizing who is behind the operations and the spam they send.</p>
<p>Spamhaus believes that the problem of snowshoe spam is now large enough to warrant a special response aimed specifically at it. The CSS is our response to this problem, and is a collaborative effort of Spamhaus and the CBL.
</p></blockquote>
<p><b>12. What trips a CSS listing – spamtraps?</b></p>
<p>Spamhaus mentions that they are working with the CBL, which implies that much of the detection is based on traps.</p>
<p><b>13. How real-time are the [SBL] listings? In other words, if you sent something a week ago, could that cause you a listing now, or does it happen from the most recent mail only?</b></p>
<p>My understanding of the SBL is that it&#8217;s a manually curated list, based on a huge amount of automatically collected information. I&#8217;m sure listing speed is based on whether someone is awake and ready to hit the button.</p>
<p><b>14. It&#8217;s clear from Spamhaus &#8216;recent SBL listings&#8217; tracking list that the vast majority of SBLs are related to criminal behavior, most of which involves truly nefarious and malicious activity. It&#8217;s also clear from most of Spamhaus ISP &#8216;users&#8217; that they no longer deliver most &#8216;spam&#8217; or even &#8216;bacn&#8217; to the Inbox and their filters are highly customized to identify unwanted messaging from dedicated IP address senders. So why does Spamhaus continue to believe that their resources should be spent blocking legitimate commercial email where there is clearly a larger need to maintain focus on the criminal actors, as well as the diminishing needs by their &#8216;users&#8217; to block legitimate (ie; dedicated and transparent) commercial emailers?</b></p>
<p>Because that &#8220;legitimate&#8221; spam you&#8217;re talking about is still painful for end users. If Spamhaus was doing consumers a dis-service, then receivers would stop using the Spamhaus list. Yet, they continue using it&#8230; I think that provides all the clarification I need that Spamhaus is doing good work.</p>
<p><b>15. [Not a question]</b></p>
<p><b>16. Can you confirm that spamtraps do not open, click or otherwise show engagement? In other words, if a client does have a spamtrap within their list, would removing or double opting in inactive subscribers help eliminate the trouble address?</b></p>
<p>It would be very bad form for a spam trap to process URLs in a message and open them. As you can imagine, someone trying to figure out which addresses are traps could simply send a whole lot of email with a bunch of unique URLs in each message, and then wait for the URLs to be queried by the trap collector. The URL hits could be correlated to determine the identity of the traps&#8230;</p>
<p>Visiting URLs in any sort of automated manner from trap traffic is a bad idea.</p>
<p><b>17. Does Spamhaus report traps hit immediately? For example, if a long standing client is reported for hitting traps, is it safe to say it was from a recent upload or signups?</b></p>
<p>Not necessarily immediately.</p>
<p><b>18. Besides typo, harvested, purchased, and recycled spamtraps, is there any other way a trap would appear in a client&#8217;s list?</b></p>
<p>None that I can think of.</p>
<p><b>19. What if someone manages to identify a spam trap&#8217;s identity and enroll it on a competitor&#8217;s mailing list? How lenient is Spamhaus to these issues knowing they exist?</b></p>
<p>If the competitor is using double opt-in, then it&#8217;s impossible for the spam trap to become enrolled in the competitor&#8217;s mailing list. To my knowledge, Spamhaus doesn&#8217;t click on the opt-in links for their traps&#8230;</p>
<p><b>20. Currently, we understand that typo-traps are being monitored by Spamhaus, but that they are mainly being used to advise marketers on the risks of mailing non-confirmed opt-in. Are there any plans over the next year to increase the blocking frequency and severity on marketers mailing to typo-trap addresses and domains?</b></p>
<p>I speculate that Spamhaus will increase the pressure on marketers to deal with typos somehow, so long as marketers continue to not get the message on this topic.</p>
<p><b>21. How many different types of spam-traps does Spamhaus monitor, and are some traps more dangerous than others?</b></p>
<p>Spam traps break down into essentially two types:</p>
<ul>
<li>Dedicated trap domains &#8211; these can be old expired domains that are picked up and registered anonymously, then allowed to &#8220;settle down&#8221; for a long period of time to ensure that no legitimate email would reasonably be sent to the domain&#8217;s users; or, they can be newly registered domains, from which trap addresses are created and then disseminated to spam lists via a variety of means (typically placing trap addresses on web sites to be &#8220;discovered&#8221;); and,</li>
<li>Embedded traps &#8211; these are email addresses that are hosted on popular receiver services, which makes them hard to spot based on domain name alone.</li>
</ul>
<p>It hardly matters how the trap address is created; what matters is whether your list management practices are so irresponsible as to result in trap addresses making it on to your list. Double opt-in, combined with regular communication with the list to verify validity virtually eliminates the possibility of getting a trap onto your list.</p>
<p><b>22. If a marketer is mailing to a purchased list of all actively engaged recipients (opening and clicking their emails regularly), do they still run the risk of hitting spam traps?</b></p>
<p>Yes, to the extent that the purchased list may contain spam trap addresses. I suppose that if the list seller could somehow prove that all of the addresses on the list recently showed activity, then the risk of hitting a trap would be reduced. But definitely not eliminated altogether. Purchasing a list is still not &#8220;best practices&#8221; because list recipients probably didn&#8217;t intend to receive mail from the buyer of the list when they signed up&#8230; This is going to lead to complaints.</p>
<p><b>23. Can you confirm that Spamhaus has a lower tolerance for newly allocated domains and IPs?</b></p>
<p>I would say definitely on this one. The age of domains and the reputability of the registrar are both very important indicators of risk to an email receiver. In the IP address world, receivers look at the sending history of the IP, its subnet, and the network (autonomous system number). The &#8220;newness&#8221; of an IP address is hard to establish; however, it&#8217;s not hard to establish that an IP has only recently started sending email. Traffic coming from a newly sending IP is definitely treated with suspicion.</p>
<p><b>24. Based on a sender&#8217;s business model, reaching out to their customers every 2, 3, or even 4 years may be necessary or applicable business practice. (example: purchasing a new car, TV, kitchen appliance). If this is necessary business practice, how can a sender do this safely without risking hitting too many traps?</b></p>
<p>I believe best practices is to reach out more frequently than once a year, requesting the recipient opt-in to the list again to continue receiving updates. I would suggest a quarterly reach-out, providing some valuable new information, and requesting a click to opt-in to further communication. For example, a company sending out warranty notifications could use the warranty mailing list to inform customers a) that they still have a warranty, b) that it is still valid, and c) of any updates to warranty servicing policies that are highly relevant to the customer.</p>
<p>If you used double opt-in to add the customer in the first place, then there shouldn&#8217;t be any problem hitting traps, so long as you prune the list if the recipient doesn&#8217;t continue to opt-in year after year.</p>
<p><b>25. What qualifies a domain for listing on the DBL? How is this different from listing the sending IPs instead on the SBL or CSS lists.</b></p>
<p>Spamhaus won&#8217;t reveal the precise list of things that qualify a domain for listing on the DBL. Generally speaking, if the domain is associated with spamming activity, then it may become listed. &#8220;Associated&#8221; could mean a number of things, including</p>
<ul>
<li>Being registered at a domain registrar that is known to register domains used for spamming, and who doesn&#8217;t respond to take-down requests;</li>
<li>Being included in spam emails, or emails providing links to malware;</li>
<li>Being associated with IP addresses that are used for sending spam.</li>
</ul>
<p><b>26. What business hours do Spamhaus employees work? Or, what is the best time to reach out to Spamhaus?</b></p>
<p>Spamhaus is a global operation, with researchers across every conceivable time zone. I don&#8217;t think there is a best time to reach out.</p>
<p><b>27. Will Spamhaus ever engage in a phone-call with Marketers? [When asked for clarification, he said he means one-on-one calls with marketers who have gotten in trouble, or, say, a monthly conference call. I think the short answer is no for practicality and safety reasons, but maybe you can elaborate.]</b></p>
<p>This is doubtful &#8211; what information would Spamhaus usefully receive in a phone call that the marketer can&#8217;t communicate via email?</p>
<p><b>28. What information must be collected in order to provide evidence that a subscriber opted in to receive a commercial email?</b></p>
<p>I would question the usefulness of providing this information to Spamhaus. If your IP or domain have become listed, it&#8217;s probably because of a spam trap hit, and in that case, Spamhaus is unlikely to care that one subscriber was added via double opt-in, if clearly some other subscribers were added in another way. But, if you&#8217;re going to send anything to prove you are following best practices, then definitely the dates, times, and IP addresses involved in the double opt-in process would be a good starting point.</p>
<p><b>29. If an ESP sends mail for multiple clients on a shared range of IP addresses and uses a shared sending domain, what is the best way to work with Spamhaus to resolve a block listing issue for an offending client while maintaining service for the rest of the clients on the range?</b></p>
<p>If at all possible, send mail through a variety of different IP addresses and different reverse domains, and then separate your traffic based on your own intensive tracking of sender behaviour. You know more about your senders than Spamhaus does. Put the new senders on one IP address; high volume guys on another, etc. At the very least, this will hopefully keep the bad guys isolated so that the listing doesn&#8217;t negatively affect your good customers.</p>
<p>But, overall, if you want to have a successful ESP business, you need to get rid of the bad guys quickly.</p>
<p><b>30. If an ESP sends mail for multiple clients on a shared range of IP addresses and the sending domain for each is a separate sub-domain, what is the best way to work with Spamhaus to resolve an issue for an offending client while maintaining service for the rest of them?</b></p>
<p>The same advice as above. Sub-domains are not that useful. IP reputation is paramount, because IPs are in short supply, and impossible to spoof.</p>
<p><b>31. Is there any risk to having multiple, separate sub-domains of a single parent domain, each sending mail for different clients or are the domains treated entirely separately? (ex: branda.maindomain.com, brandb.maindomain.com, brandc.maindomain.com)</b></p>
<p>There is no easy answer to this, but I will suggest that registering separate top level domains costs more, and is therefore probably &#8220;better&#8221;.</p>
<p><b>32. Do they open/render images on emails they receive? If so, how would they expect a marketer to distinguish that from ‘real’ engagement?</b></p>
<p>I speculate that Spamhaus does not fetch image links, because that would permit senders to track opens by the traps and may lead to trap discovery. A small sample of such image URLs may be fetched, but certainly not every single one.</p>
<p><b>33. Ditto for clicks. Do they follow any of the links in the emails they receive?</b></p>
<p>See my answer above.</p>
<p><b>34. Are blacklistings all done by humans or are some automatically triggered by the receipt of *any* emails to an address? In other words, does the *content* or *purpose* of the message matter at all, or is it simply the fact an email was received? And if it is reviewed, are there formalized criteria for this evaluation?</b></p>
<p>The content or purpose of email messages sent to a trap is not important. The fact that you tried to deliver something to a trap exposes that your list management is broken. Listings on the CBL (and therefore the XBL) are driven entirely automatically, based on trap networks. The SBL is more manually driven; however, the input to the manual process is to a large extent trap activity.</p>
<p><b>35. Do they collaborate with other blacklist providers? E.g. is it possible to get listed (or a listing escalated) within Spamhaus because of ‘hits’ elsewhere or visa-versa?</b></p>
<p>I would suggest that cooperation between blacklists is minimal, for a variety of reasons.</p>
<p><b>36. Are decisions to blacklist made by any of the ‘volunteers’? is there a QC or review process internally?</b></p>
<p>I don&#8217;t know for sure, but I would speculate that all Spamhaus researchers &#8212; whether they are volunteers or paid &#8212; are able to make listing decisions.</p>
<p><b>37. Given that Spamhaus participants are all volunteers, how do they enforce consistent review and blacklisting behavior?</b></p>
<p>I don&#8217;t think it&#8217;s true that all Spamhaus researchers are volunteers. And in any case, I don&#8217;t see how this would really matter. The Catholic Church is volunteer driven, and yet is quite effective at being one of the largest and wealthiest organizations on the planet.</p>
<p><b>38. Why do they sometimes just list the offending IPs, but other times appear to name and attack specific marketing brands?</b></p>
<p>Because sometimes it&#8217;s effective to name the responsible brand rather than just the IP. Think of it this way: If only the IP is listed, then the brand can simply switch to a new ESP and get away with a few more blasts. If the brand is named, then the ESPs know they can&#8217;t take the brand on as a customer, or else they risk a listing. It&#8217;s a tool to enforce good behaviour in an efficient and rapid manner.</p>
<p><b>39. What do they say to claims they are unfairly targeting legitimate marketers?</b></p>
<p>First, define the term &#8220;legitimate marketer&#8221;. Is a &#8220;legitimate marketer&#8221; one that always uses double opt-in, never buys lists, and always sends email messages that recipients clearly want to receive? If this is the definition of a legitimate marketer, then the risk of a listing for that legitimate marketer is close to zero. The fact that you are using the word &#8220;targeting&#8221; indicates that you are probably not a legitimate marketer.</p>
<p><b>40. What’s their opinion of list rental or other one-time *opt-in* offers to an email address?</b></p>
<p>A list rental is not much different from a list buy; the recipients opted (if they opted at all) to receive one type of communication, and then ended up getting another. That&#8217;s spam.</p>
<p><b>41. Typos &#038; errors happen. What thresholds is Spamhaus using to avoid accidental listings and/or what can marketers do to avoid?</b></p>
<p>I would imagine the thresholds are quite lenient in most cases, because Spamhaus has an extremely satisfying false positive ratio. If they didn&#8217;t, then receivers would stop using Spamhaus, and the project would fail.</p>
<p><b>42. Could they imagine cooperating with the DMA and if so, what would that look like?</b></p>
<p>I think you should ask the second question first. What value would there be to Spamhaus and email receivers to cooperate with an organization that actively promotes breaking best practices in order to get email delivered to unsuspecting consumers? Spamhaus is a sponsor and active participant in M3AAWG, and therefore I would recommend becoming a member of that organization and others like it if you wish to have face time with Spamhaus.</p>
<p><b>43. What can hosting networks do to get off Spamhaus?</b></p>
<p>Hosting providers need to track the sending behaviour of their customers using inline spam filtering technology. They should also actively monitor feedback loops, and apply best practices when vetting new customers. Customers who look bad to begin with, or turn bad based on metrics, need to be throttled back or kicked off the network. The positive result of this for the hosting provider is that spammers will tend to avoid even trying to sign up for an account on the network. Eventually, this leads to a reduction in credit card chargebacks, and of course better delivery rates for the good customers. Everyone wins.</p>
<p><b>44. I run abuse for a hosting provider in the US. We&#8217;ve had our share of SBL and XBL listings, and have responded by tuning in to feedback loops and aggressively removing customers who trigger listings and complaints. We also thoroughly vet new customers using a credit card fraud service as well as telephone verification, captchas, and other techniques. With all this being said, the problem is that mail still flows out of our customers&#8217; servers (which we don&#8217;t control, because they are dedicated and VPS servers). How can we block the spam proactively? Is there a way that Spamhaus could send us feedback data other than a blacklisting? Can anyone else help with this?</b></p>
<p>Same answer as the above, with a focus on inline transparent SMTP filtering.</p>
<p><b>45. How has your business, mission, and the industry of blacklists changed over time? We first started working with Spamhaus in year 2000 and found that Spamhaus only listed networks that were known for sending majority spam, with very little legitimate email being blocked. As the years have gone by, it seems that Spamhaus is taking a more aggressive approach by listing some networks that send all opt-in email and their only flaws are typos and being single opt-in. Is our perception off? Where does Spamhaus see the future and how might that change over time?</b></p>
<p>Spamhaus has had to adapt over time to the changing practices of senders. Networks need to be listed occasionally in order to encourage the right behaviour &#8211; such as kicking out a bad customer who is snow-shoeing. A listing that seems only peripherally related, such as the listing of Cloudflare for permitting malware hosting a bit too liberally, is important because it provide a financial incentive to the organization to deal with the problematic behaviour.</p>
<p><b>46. Spamhaus has always been clear on recommending Confirmed-Opt-In email address collection. I am sure you know most legitimate mailers, including large corporations use single opt in. Is it part of Spamhaus’s mission or intention to blacklist list all companies that do not use confirmed-opt-in? How does Spamhaus determine which companies to list and which ones to not list? Many fortune 500 companies do not use confirmed-opt-in and most are not listed by Spamhaus. Does Spamhaus fear they could lose credibility by listing companies like GAP and other who play by most of the right rules with only typos and single opt-in being the only tarnish on their record?</b></p>
<p>Spamhaus will continue pushing for confirmed opt-in (i.e. double opt-in) until the end of time. It&#8217;s the only way to reliably guarantee that the recipient really does intend to receive communication from the sender.</p>
<p><b>47. Most consumers are not used to getting confirmation messages when they sign up for an email list. Unless consumers receive the confirmation right away, they are afraid to click on emails they don’t recognize for fear or phishing, viruses, and so forth. Even those that do receive the confirmation right away could be weary. I believe this is one of the reasons that legitimate companies do not use confirmation messages. How does Spamhaus suggest companies handle this? Before it becomes commonplace, there needs to be a tipping point to get consumers used to seeing and acting on confirmation messages. When does Spamhaus see this tipping point happening? In the past 13 years, I have not seen the majority of the marketplace adopt confirm opt-in.</b></p>
<p>This is a lame excuse for not using confirmed opt-in.</p>
<p><b>48. Lastly, we ask that Spamhaus be more clear when describing each section and also when responding to some of their listings. Spamhaus SBL in our experience is very responsive and easy to work with. Our concern is with the CBL (Composite Blocking List). The CBL web page says they only list IPs with spambot or virus like activity. It does not clearly explain that the CBL also operates spamtrap that can list legitimate mail servers IP. We once were listed for two weeks while we researched what could have been causing the issue (looking for misconfigurations, virus like activity, etc.) only to learn that the CBL administrators were upset and listed some of our IPs because they received one of our emails to their spamtrap. CBL administrators were not clear about this when we reached out to them as to what the problem was. They replied with terse replies like “This needs to stop”, but not explaining what needs to stop (was it a header problem, a spam problem, etc.). Please have the CBL administrators be more clear on if listings are caused by virus/bot like activity or if they were spammed. I am sure you know that a spamhaus listing is devastating to a marketer and yes, 60% of email bounces when blocked by spamhaus.</b></p>
<p>You need to understand that Spamhaus and the CBL are not large organizations with endless resources to deal with de-listing requests. They need to work efficiently, and focus most of their efforts on the core work of identifying badness.</p>
<p><b>49. What is the risk of a single “typo” email record?  If the record is mailed once, but not ever again, is that enough to get listed?  Is it true that a sender will get a warning first, and then if non active records are mailed again, that is when the block is placed?  (If  a person submits their email address, how can a marketer know if it’s good if we don’t mail it at least once?)</b></p>
<p>A single typo is pretty low risk today, but I can see that risk level rising over time as more stores allow customers to input their email address to receive a receipt. The best way to deal with this problem is to send an opt-in confirmation, or to rely on a separate authentication system such as allowing the customer to log in using their Google or Facebook account rather than manually entering in their email address.</p>
<p><b>50. Do Spamhaus volunteers take “complaints” from other people, or are they only identifying “bad actors” based on personal receipt of a message?</b></p>
<p>This is unknown.</p>
<p><b>51. How many volunteer complaints are required to flag a sender?  (One?  Ten?)  Is this tracked at the individual level or just total? For example, one volunteer who complains five times counts as one or five?</b></p>
<p>I suspect Spamhaus is not going to share the answer to this. But I also point out that you don&#8217;t understand how Spamhaus volunteers work. They&#8217;re not so much volunteers, as hard working security researchers, who are highly trusted and skilled. They are &#8220;paid&#8221; in the satisfaction of dealing with a very large problem and making a huge difference for hundreds of millions of people every day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2013/03/fifty-questions-for-spamhaus-with-our-answers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Screencast: Outbound spam filtering for hosting providers</title>
		<link>http://www.mailchannels.com/blog/2013/03/new-screencast-outbound-spam-filtering-for-hosting-providers/</link>
		<comments>http://www.mailchannels.com/blog/2013/03/new-screencast-outbound-spam-filtering-for-hosting-providers/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 23:30:38 +0000</pubDate>
		<dc:creator>d.liao</dc:creator>
				<category><![CDATA[Videos]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=619</guid>
		<description><![CDATA[Watch MailChannels CEO, Ken Simpson, talk about outbound spam from the web hosting perspective. Learn how the MailChannels platform identifies and blocks spam, leading to a &#8220;blacklist free network&#8221;. Transparent Spam Filtering for Hosting Companies from MailChannels on Vimeo.]]></description>
			<content:encoded><![CDATA[<p>Watch MailChannels CEO, Ken Simpson, talk about outbound spam from the web hosting perspective. Learn how the MailChannels platform identifies and blocks spam, leading to a &#8220;blacklist free network&#8221;.</p>
<p><iframe src="http://player.vimeo.com/video/61575402" width="600" height="337" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe>
<p><a href="http://vimeo.com/61575402">Transparent Spam Filtering for Hosting Companies</a> from <a href="http://vimeo.com/mailchannels">MailChannels</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2013/03/new-screencast-outbound-spam-filtering-for-hosting-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Screencast: MailChannels transparent antispam introduction for ISPs</title>
		<link>http://www.mailchannels.com/blog/2013/03/new-screencast-mailchannels-transparent-antispam-introduction-for-isps/</link>
		<comments>http://www.mailchannels.com/blog/2013/03/new-screencast-mailchannels-transparent-antispam-introduction-for-isps/#comments</comments>
		<pubDate>Fri, 08 Mar 2013 19:37:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Videos]]></category>
		<category><![CDATA[outbound spam]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=600</guid>
		<description><![CDATA[MailChannels CEO introduces our transparent outbound spam filtering technology in an informative five minute screencast. Click below to view:]]></description>
			<content:encoded><![CDATA[<p>MailChannels CEO introduces our transparent outbound spam filtering technology in an informative five minute screencast. Click below to view:</p>
<p><iframe src="http://player.vimeo.com/video/61371966" frameborder="0" width="600" height="400"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2013/03/new-screencast-mailchannels-transparent-antispam-introduction-for-isps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>World&#8217;s largest spam sources are all hosting companies</title>
		<link>http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/</link>
		<comments>http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/#comments</comments>
		<pubDate>Fri, 01 Mar 2013 22:47:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trend Analysis]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=590</guid>
		<description><![CDATA[Over the past twelve months, there has been a dramatic shift in the world&#8217;s spam. Whereas twelve months ago, much of the world&#8217;s spam originated from botnet-controlled PCs on ISP networks, most of the world&#8217;s spam volume now originates from web hosting provider networks. This is an anachronism in many ways, because in the early [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/blog/03-01-2013-header.jpg" width=500 height= 262 alt="STRATOS home page graphic"></p>
<p>Over the past twelve months, there has been a dramatic shift in the world&#8217;s spam. Whereas twelve months ago, much of the world&#8217;s spam originated from botnet-controlled PCs on ISP networks, most of the world&#8217;s spam volume now originates from web hosting provider networks. This is an anachronism in many ways, because in the early days of spam, spammers would colocate their spamming machines in web hosting networks. These days, spammers rent VPS (cloud) servers and abuse shared hosting platforms via compromised scripts and other badness.</p>
<p>The <a href="http://cbl.abuseat.org">Composite Blocking List</a> (CBL) maintains a really fantastic set of statistics on the worst spam sources according to their spam trap network &#8211; here&#8217;s the link: <a href="http://cbl.abuseat.org/statistics.html">cbl.abuseat.org/statistics.html</a>. CBL operates one of the world&#8217;s most comprehensive spam trap networks, which is probably why <a href="http://www.spamhaus.org/">Spamhaus</a> uses CBL data to power its own widely used <a href="http://www.spamhaus.org/xbl/">Exploits Block List</a> (XBL).</p>
<p>I thought it would be interesting to look at the companies that are on the top of the CBL&#8217;s <a href="http://cbl.abuseat.org/asntraffic.html">spam volume report</a>, which summarizes the networks that send the most spam messages to the CBL&#8217;s spam trap addresses.</p>
<p>At the top of the list, we have &#8220;The Planet&#8221;, otherwise known as <a href="http://www.softlayer.com">SoftLayer</a>. Their network of 1.5M IP addresses sends fully 3.5% of the spam volume received by CBL. SoftLayer is a truly enormous web hosting company, with multiple massive data centers, and 436 employees (according to <a href="http://www.linkedin.com/company/95291">LinkedIn</a>). I know that SoftLayer has an active abuse team; however, they seem to be fighting a losing battle with the spammers at this moment in time.</p>
<p>Next up is STRATO, a German web hosting provider which advertises ultra low cost domain registration and shared web hosting. Looks like they have a lot of compromised hosting accounts in their network. With 81 employees on LinkedIn, they might want to look at allocating a bit more of their staff time to abuse.</p>
<p>Thirdly, we have <a href="http://www.redmon.com">Redmon Group</a>. I tried to find Redmon Group on LinkedIn, but failed. Yet, they somehow generate more han 2.5% of CBL&#8217;s spam trap volume, and operate a network with more than 300,000 IP addresses. On their web site, Redmon Group advertises, rather vaguely, &#8220;Redmon Group is a nationally acclaimed interactive media firm that develops interactive technology products and services to enable, train, and entertain. Founded in 1990, Redmon works with a diverse group of distinguished clients including corporate, public sector, international, and educational organizations. The company has developed over 300 custom products for over 100 different clients.&#8221; All I can say is, &#8220;Hmmmm&#8221;.</p>
<p>Rounding out the rest of the top-25 spam sources on the CBL list, we have just six ISPs; the rest are web hosting providers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Release 2.5 Announcement</title>
		<link>http://www.mailchannels.com/blog/2012/12/release-2-5-announcement/</link>
		<comments>http://www.mailchannels.com/blog/2012/12/release-2-5-announcement/#comments</comments>
		<pubDate>Wed, 12 Dec 2012 21:04:56 +0000</pubDate>
		<dc:creator>ksimpson</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=583</guid>
		<description><![CDATA[MailChannels has released its version 2.5 email filtering platform. This blog post describes what's new in 2.5.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m pleased to announce the 2.5 release of the MailChannels platform. This release comes six months after our 2.0 release, bringing with it substantial improvements in a number of key areas. I&#8217;ll highlight just a few of the major improvements in this blog post; however, I encourage our users to visit our <a href="https://mailchannels.zendesk.com/forums/21030908-customer-knowledge-base">customer knowledge base</a> for the full details.</p>
<h2>Performance Improvements</h2>
<p><img src="http://farm9.staticflickr.com/8453/7905148058_08330ff82d_n_d.jpg" style="float:right"></p>
<p>Performance is a key differentiating factor in the MailChannels outbound email filtering solution &#8211; whether it&#8217;s processing mail quickly or handling enormous connection concurrency, we aim to be the fastest in the world. The 2.0 release introduced a lot of new features, and making those features run fast at scale is something we&#8217;re obviously highly committed to. We&#8217;re processing upwards of 20,000 connections <em>per second</em> at some of our larger sites, and this level of traffic, combined with the extensive user behaviour tracking capabilities in the 2.0 platform had challenged some of our design assumptions. In 2.5, performance is greatly improved when fetching large sets of behaviour data for a sender. Database compaction settings have been optimized, reducing lookup times, conserving disk space, and improving write speeds. And we have implemented a better data expiry approach that further improves performance and reduces disk space requirements.</p>
<h2>APIs</h2>
<p><img src="http://farm2.staticflickr.com/1196/1267682594_fcd2db9cae_m.jpg" style="float:right"></p>
<p>MailChannels customers tend to be control freaks, with a penchant for programming. For this reason, we have added APIs allowing the programmatic control of almost every aspect of our solution. These new APIs make it possible to fully automate the deployment of the MailChannels solution using tools like <a href="http://www.opscode.com/chef/" rel="nofollow">Opscode Chef</a>. Use our APIs to search message delivery logs, manipulate policy scripts and lists, and change configuration settings across entire clusters.</p>
<h2>RedHat Enterprise Support</h2>
<p><img src="http://farm4.staticflickr.com/3079/2379832378_b5da420cb0_m_d.jpg" style="float:right"></p>
<p>You asked, and we&#8217;ve heard you. MailChannels has long supported Ubuntu because of its out-of-the-box kernel support for transparent proxying. The RedHat Enterprise 6.0 release added this goodness to the kernel, so we decided it was high time to publish officially supported RedHat packages. For repository information, please contact support.</p>
<h2>Monitoring Service</h2>
<p><img src="http://farm1.staticflickr.com/44/147208226_db72b030bc_m_d.jpg" style="float:right"></p>
<p>We often provide a &#8220;high touch&#8221; relationship with our customers. Over the years, we built up server monitoring capabilities for some higher end customers. We&#8217;ve now standardized that offering and have added specific tools to monitor the health of email traffic. Monitoring is available for a reasonable monthly or annual fee. <a href="/company/contact-sales.html">Ask us</a> for more information about this new service.</p>
<h2>Other Stuff</h2>
<ul>
<li><code>XCLIENT</code> support &#8211; for Postfix junkies, <code>XCLIENT</code> support means we can pass the original IP address and RDNS information to your downstream Postfix box. Useful for intercepting mail from authenticated users before a Postfix box processes it.</li>
<li>LDAP authentication &#8211; you can now configure the web console to authenticate users via LDAP (aka Active Directory).</li>
<li>Customizable email notification templates &#8211; policy scripts can send notifications when interesting things happen (such as a user starting to send spam). Customizable templates mean you can customize the notification messages.</li>
<li>Policy logging &#8211; in 2.0 we introduced a JavaScript engine for writing email policy scripts. Now you can enable detailed logging of each policy script execution, which can help to track down issues.</li>
</ul>
<p>We look forward to our next major release, which is slated for mid-2013. Until then, don&#8217;t hesitate to file a ticket with our support system if you have any additional questions about this release. If you&#8217;re a customer, we&#8217;ll be contacting you soon with instructions for upgrading.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/12/release-2-5-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AOL accidentally rejects millions of messages</title>
		<link>http://www.mailchannels.com/blog/2012/10/aol-accidentally-rejects-millions-of-messages/</link>
		<comments>http://www.mailchannels.com/blog/2012/10/aol-accidentally-rejects-millions-of-messages/#comments</comments>
		<pubDate>Tue, 16 Oct 2012 18:46:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trend Analysis]]></category>
		<category><![CDATA[smtp errors]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=581</guid>
		<description><![CDATA[AOL started rejecting connections instead of temp-failing them, under certain conditions. This has resulted in a major increase in non-delivery receipts worldwide.]]></description>
			<content:encoded><![CDATA[<p>AOL&#8217;s mail servers recently started issuing permanent failure notices with an encouragement for the sender to &#8220;try again later&#8221;:</p>
<pre>
521 5.2.1 Service unavailable. Please try again later.
</pre>
<p>Normally, if a mail server wishes to temporarily reject a connection or message, it will respond with a 400-series error such as &#8220;421 Try again later&#8221;. When the sending mail server sees this error code, it&#8217;s supposed to queue the message up and try again later. When a 500-series error is encountered &#8212; regardless of the text of the error message &#8212; the sending server is supposed to stop trying to send the message, and generate a bounce message to the original sender.</p>
<p>The impact of this change, whether AOL intended it or not, is that many users (potentially millions) have received non-delivery receipts with &#8220;521 5.2.1 Service unavailable. Please try again later.&#8221; in their inboxes, rather than merely experiencing a brief delay in message delivery to their friends at AOL.</p>
<h2>What can I do if I get this error?</h2>
<p>Not much, unfortunately, other than to try sending the message again. Hopefully AOL will transform these 500-series errors into 400-series errors, and the mail servers of the world can resume queueing on our behalf when AOL&#8217;s mail servers are overloaded.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/10/aol-accidentally-rejects-millions-of-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why is Verizon blocking my mail with &#8220;571 Email from 1.2.3.4 is currently blocked by Verizon Online&#8217;s anti-spam system.&#8221;</title>
		<link>http://www.mailchannels.com/blog/2012/10/why-is-verizon-blocking-my-mail-with-571-email-from-1-2-3-4-is-currently-blocked-by-verizon-onlines-anti-spam-system/</link>
		<comments>http://www.mailchannels.com/blog/2012/10/why-is-verizon-blocking-my-mail-with-571-email-from-1-2-3-4-is-currently-blocked-by-verizon-onlines-anti-spam-system/#comments</comments>
		<pubDate>Fri, 05 Oct 2012 22:24:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[smtp errors]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=576</guid>
		<description><![CDATA[We demystify the 571 error code sometimes returned by Verizon's mail servers.]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm7.staticflickr.com/6117/6280612579_635588e791_d.jpg" alt="Weird young people" width=500 height=500 /></p>
<p>In this latest post of a series of blog posts where we attempt to demystify the most common SMTP error codes, today we discuss Verizon&#8217;s ubiquitous rejection code:</p>
<p><code>Email from xx.57.168.45 is currently blocked by Verizon Online's anti-spam system. The email sender or Email Service Provider may visit <a href="http://www.verizon.net/whitelist">http://www.verizon.net/whitelist</a> and request removal of the block. 123929</code></p>
<h2>What does it mean?</h2>
<p>Verizon&#8217;s email systems have rejected your message because the IP address of your mail server has been blacklisted by Verizon&#8217;s internal IP reputation system. It&#8217;s likely that your mail server is blocked because of recent bad behaviour such as sending spam, or email content about which Verizon customers have complained.</p>
<p>Verizon describes the error on their web page:</p>
<blockquote><p>
To protect our members and our network from unsolicited e-mail (spam), Verizon Online has put measures in place to restrict the distribution of e-mail containing spam and potentially harmful viruses to our members. If we review a restricted e-mail address or domain and determine, based on the information available, that it does not pose a current unacceptable risk to our members or our network, the e-mail address or domain can be &#8220;whitelisted&#8221; and, therefore, e-mail delivery will be allowed to your mailbox.
</p></blockquote>
<h2>What can I do?</h2>
<p>If you are confident that your mail server is not sending Verizon spam or other objectionable content, then you can request that Verizon add its IP address to a whitelist. You will need to fill in their <a href="http://my.verizon.com/micro/whitelist/RequestForm.aspx?id=isp>whitelist request form</a>. Verizon will then consider adding your IP to its whitelist; however, there is no guarantee that this will happen, and you may not get feedback from Verizon to confirm whether or not it has.</p>
<h2>What else can I try?</h2>
<p>AOL provides excellent guidelines for ISPs. Yes, AOL. I mention AOL because Verizon doesn&#8217;t offer a lot of helpful advice on its web site to assist senders.</p>
<ol>
<li>Carefully review AOL&#8217;s <a href="http://postmaster.aol.com/"Postmaster web site</a> and follow their recommended best practices.</li>
<li>Review Verizon&#8217;s <a href="http://www22.verizon.com/ResidentialHelp/DialUp/Email/Blocked+Email/QuestionsOne/85702.htm">brief help page</a> regarding email deliverability.</li>
<li>Install outbound spam filtering, track your users&#8217; behaviour, and shut down abusive accounts in your own network.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/10/why-is-verizon-blocking-my-mail-with-571-email-from-1-2-3-4-is-currently-blocked-by-verizon-onlines-anti-spam-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How web hosting providers can battle fraudulent sign-ups</title>
		<link>http://www.mailchannels.com/blog/2012/10/how-web-hosting-providers-can-battle-fraudulent-sign-ups/</link>
		<comments>http://www.mailchannels.com/blog/2012/10/how-web-hosting-providers-can-battle-fraudulent-sign-ups/#comments</comments>
		<pubDate>Tue, 02 Oct 2012 21:08:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Trend Analysis]]></category>
		<category><![CDATA[fraudulent sign-ups]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[iaas]]></category>
		<category><![CDATA[spamhaus]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=571</guid>
		<description><![CDATA[Spamhaus recently released an excellent guide for hosting providers describing how to avoid signing up fraudulent customers. In this blog post, we summarize Spamhaus' recommendations.]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm4.staticflickr.com/3508/3819016262_e375b9791b.jpg" alt="Man with hat" /></p>
<p>Back in February 2012, we blogged about <a href="http://www.mailchannels.com/blog/2012/02/outbound-spam-filtering-for-iaas-providers/">the fraudulent sign-up problem at IaaS providers</a>. Today, Spamhaus posted a lengthy, extremely helpful guide for IaaS providers (they call them hosting providers) discussing <a href="http://www.spamhaus.org/news/article/687/how-hosting-providers-can-battle-fraudulent-sign-ups" target="_new">how they can best avoid taking on new customers who will abuse their services</a>.</p>
<p>Fraudulent sign-ups are a major problem for web hosting providers &#8211; particularly for providers offering Virtual Private Servers (VPS&#8217;s) and other flexible hosting options. Spammers take advantage of these services to set up spamming operations and trade on the good name and IP reputation of the provider.</p>
<p>Spamhaus recommends several steps that hosting companies can take to prevent fraudulent sign-ups. I&#8217;ll summarize their recommendations, and add some of my own:</p>
<ul>
<li>Verify User Information &#8211; Confirm the user&#8217;s identity via SMS, a callback, or some other &#8220;out of band&#8221; method. This helps to filter out some of the automated methods spammers use to create large numbers of accounts with fictitious identities.</li>
<li>Blacklist Abusive Customers &#8211; When customers mis-behave, add their details to a blacklist. Consult this blacklist whenever someone tries to sign up for a new account, and prevent the same blacklisted person from signing up again.</li>
<li>Have a Strong Acceptable Use Policy (AUP) &#8211; Make sure you have the legal backing to terminate bad customers by having a strong AUP. Spamhaus even offers a point-and-click &#8220;<a href="http://www.spamhaus.org/isp/aup_builder/" target="_spamhaus">AUP generator</a>&#8220;</li>
<li>Monitor Traffic &#8211; Actively monitor traffic entering and leaving your network. Sign up for &#8220;feedback loops&#8221; (<a href="http://en.wikipedia.org/wiki/Feedback_loop_(email)" target="_wikipedia">Wikipedia reference</a>) to get notifications when email recipients complain about your customers&#8217; email traffic. Implement an <a href="http://www.mailchannels.com">outbound email filter</a>.</li>
<li>Verify Customer IP Addresses &#8211; When a new user signs up, check whether their IP address is registered on a blacklist. Don&#8217;t permit sign-ups that come via the <a href="https://www.torproject.org/projects/tordnsel.html.en" target="_tor">Tor network</a>.</li>
<li>Have a Responsive Abuse Desk &#8211; Fraudsters look for hosting services with lax abuse policies and enforcement. Don&#8217;t be one of those companies. Have a well funded abuse desk, with good response times, and fraudsters will put the word out that your service is a bad place to steal business.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/10/how-web-hosting-providers-can-battle-fraudulent-sign-ups/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Why did AOL just send me &#8220;554 (RTR:BL) http://postmaster.info.aol.com/errors/554rtrbl.html&#8221;?</title>
		<link>http://www.mailchannels.com/blog/2012/10/why-did-aol-just-send-me-554-rtrbl-httppostmaster-info-aol-comerrors554rtrbl-html/</link>
		<comments>http://www.mailchannels.com/blog/2012/10/why-did-aol-just-send-me-554-rtrbl-httppostmaster-info-aol-comerrors554rtrbl-html/#comments</comments>
		<pubDate>Tue, 02 Oct 2012 15:13:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[smtp errors]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=564</guid>
		<description><![CDATA[We discuss why AOL's mail servers sometimes respond with the error message "554 (RTR:BL)" and what you can do about this error message to get email flowing again to AOL users.]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm7.staticflickr.com/6092/6273814352_0688327f65_d.jpg" alt="Hermitage Bridge, by Angus Clyne" width=500 height=397 /></p>
<p>In this latest post of a series of blog posts where we attempt to demystify the most common SMTP error codes, today we discuss AOL&#8217;s very common 554 error code:</p>
<p><code>554 (RTR:BL) <a href="http://postmaster.info.aol.com/errors/554rtrbl.html" target="_aol">http://postmaster.info.aol.com/errors/554rtrbl.html</a></code></p>
<h2>What does it mean?</h2>
<p>If you received this error message in your inbox, it means that you tried to send someone at AOL an email message, and AOL rejected the connection from your mail server because your mail server&#8217;s IP address has sent <em>a great deal</em> objectionable content such as spam to AOL. AOL states the cause on its Postmaster web site as follows:</p>
<blockquote><p>
This error message indicates that a permanent block has been placed against your IP due to poor IP reputation. Apply for a complaint feedback loop before opening a support request.
</p></blockquote>
<h2>What can I do?</h2>
<p>This error message indicates that AOL&#8217;s email systems have taken an extreme disliking to your mail server&#8217;s IP address. To get this far, you need to send AOL a large amount of spam and other objectionable material about which AOL users have complained. This is a &#8220;permanent&#8221; block, which means it&#8217;s going to take some time and serious effort to resolve the problem. <b>Solution:</b> Locate accounts that are sending spam via your mail server&#8217;s IP address, and shut them down. You probably have more than one of these.</p>
<h2>What else can I try?</h2>
<ol>
<li>Carefully review AOL&#8217;s Postmaster pages and follow their recommended best practices.</li>
<li>Sign up for a <a href="http://postmaster.aol.com/Postmaster.FeedbackLoop.php" target="_aol">feedback loop</a>, which is a mechanism that allows AOL to report user complaints directly to you so that you know what types of email AOL users object to.</li>
<li>Install outbound spam filtering, track your users&#8217; behaviour, and shut down abusive accounts in your own network.</li>
</ol>
<h2>Temporary Measures</h2>
<p>As a very temporary measure, if you can send through a different mail server, that might help to get your email delivered more reliably. For example, if you have a Gmail account, use the Gmail SMTP server to send your mail. Its host name is <code>smtp.gmail.com</code>. You&#8217;ll need to enable TLS security, and provide your username and password in order to use Gmail&#8217;s SMTP server. More information can be found on the <a href="http://support.google.com/mail/bin/answer.py?hl=en&#038;answer=13287" rel="nofollow">Google Support Site</a>. Obtaining a new IP address for your mail server may be another way of solving the problem; however, if you do this frequently, be advised that AOL will eventually figure out your game and will beging blocking larger parts of the address space from which you send.</p>
<h2>Bottom Line</h2>
<p>Fundamentally, if you see &#8220;554 (RTR:BL)&#8221;, it&#8217;s time to get serious about filtering your outbound email traffic, identifying sources of abuse such as compromised accounts, and generally improving the quality of the email you send so that AOL users don&#8217;t complain about it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/10/why-did-aol-just-send-me-554-rtrbl-httppostmaster-info-aol-comerrors554rtrbl-html/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How Botnets Send Spam (In Layman&#8217;s Terms)</title>
		<link>http://www.mailchannels.com/blog/2012/10/how-bot-nets-send-spam-in-laymans-terms/</link>
		<comments>http://www.mailchannels.com/blog/2012/10/how-bot-nets-send-spam-in-laymans-terms/#comments</comments>
		<pubDate>Mon, 01 Oct 2012 15:46:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[botnets]]></category>
		<category><![CDATA[guests]]></category>

		<guid isPermaLink="false">http://www.mailchannels.com/blog/?p=559</guid>
		<description><![CDATA[A guest blogger describes how and why spammers use bot nets to send spam.]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm1.staticflickr.com/252/514768629_5717a72c4e_d.jpg" alt="Zombie army" /></p>
<p>Today&#8217;s post comes from a mysterious guest blogger, who wishes to remain anonymous. The guest blogger is heavily involved with the Messaging, Mobile &#038; Malware Anti-Abuse Working Group (<a href="http://www.maawg.org" target="__new">M3AAWG</a>), and has a number of bot net related papers to his name. Thank you, Mr/Mrs. Anonymous.</p>
<p>Spammers would like to spam directly from their own systems, but when they do that, Spamhaus quickly notices and blocklists those addresses, making it impossible for them to deliver mail from those addresses.</p>
<p>What is the determined spammer to do? Answer, they&#8217;ll reroute their spam through someone else&#8217;s address space. That way, someone else&#8217;s address space will get blocked, not their own, and the spam will look like it&#8217;s coming from somewhere else, thereby hindering backtracking and punishment by the authorities. But how to do this?</p>
<p>Most systems don&#8217;t ship in a way that will let random 3rd parties route mail through them (although obviously at one point, many systems did ship as promiscuous open relays, accepting email from anyone anywhere and routing it to anyone anywhere).</p>
<p>These days, if you want someone else&#8217;s computer to accept and route random email for you, you need to add software to the system to intentionally make it abusable in useful ways.</p>
<p>But who&#8217;d KNOWINGLY let you screw up their system this way? Answer: no one. So spammers need to be sneaky. They use malicious software (what most people think of as &#8220;computer viruses&#8221;) to intentionally misconfigure an innocent person&#8217;s computer so that they can surreptitiously abuse it.</p>
<p>The spammer gets that software on an innocent person&#8217;s computer many different ways. Maybe they drop it on you via email, or drop it the malware when you visit a tainted web page, or you download a &#8220;free game&#8221; that turns out to have malware as well.</p>
<p>The bad guy now has an inventory of compromised systems that they can use. But, it isn&#8217;t very efficient to just use one at a time. If they can use many compromised systems in parallel, they can really hose some spam out there in volume, right? Suddenly they may be able to send spam from hundreds or even thousands of systems at once. When they do that, those compromised systems are normally referred to as bots, and the guy operating that network of botted systems is called a &#8220;botmaster.&#8221;</p>
<p>The botted systems periodically check in with one of the botmaster&#8217;s web site for instructions every so often, or listen on IRC, Twitter, or other one-to-many communication channels for work to do. At that point, like an army of mindless zombies, once the botmaster tells them what they&#8217;re to do, they unthinkingly execute those tasks.</p>
<p>Combatting the bots can happen at many different levels. Systems seen to be spewing can be identified, and then hopefully cleaned up by their owners. Network operators can use intrusion detection systems to spot anomalous traffic on their network, and then block access to the command and control servers that would like to give the local botted hosts stuff to do. And there are many other techniques that can also be used to tackle these guys, including things as simple as requiring all outbound email from customer systems to be sent via the provider&#8217;s official email servers, where the ISP can scrutinize it and automatically block any spam.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mailchannels.com/blog/2012/10/how-bot-nets-send-spam-in-laymans-terms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
